CVE-2014-5428
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to execute arbitrary code by uploading a shell script.
Vulnerabilidad de la subida de ficheros sin restricciones en servicios web no especificados en Johnson Controls Metasys 4.1 hasta 6.5, utilizado en Application and Data Server (ADS), Extended Application and Data Server (también conocido como ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, y NxE8500, permite a atacantes remotos ejecutar código arbitrario mediante la subida de una secuencia de comandos de shell.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-08-22 CVE Reserved
- 2015-03-29 CVE Published
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-14-350-02 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Application And Data Server Search vendor "Johnsoncontrols" for product "Application And Data Server" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Extended Application And Data Server Search vendor "Johnsoncontrols" for product "Extended Application And Data Server" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Lonworks Control Server Lcs8520 Search vendor "Johnsoncontrols" for product "Lonworks Control Server Lcs8520" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5510-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5510-2u Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2u" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5511-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5511-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5520-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5520-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5521-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5521-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Integration Engine 5510-2 Search vendor "Johnsoncontrols" for product "Network Integration Engine 5510-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Integration Engine 5511-2 Search vendor "Johnsoncontrols" for product "Network Integration Engine 5511-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Nxe8500 Search vendor "Johnsoncontrols" for product "Nxe8500" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Application And Data Server Search vendor "Johnsoncontrols" for product "Application And Data Server" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Extended Application And Data Server Search vendor "Johnsoncontrols" for product "Extended Application And Data Server" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Lonworks Control Server Lcs8520 Search vendor "Johnsoncontrols" for product "Lonworks Control Server Lcs8520" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5510-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5510-2u Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2u" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5511-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5511-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5520-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5520-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5521-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5521-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Integration Engine 5510-2 Search vendor "Johnsoncontrols" for product "Network Integration Engine 5510-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Integration Engine 5511-2 Search vendor "Johnsoncontrols" for product "Network Integration Engine 5511-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Nxe8500 Search vendor "Johnsoncontrols" for product "Nxe8500" | - | - |
Safe
|